1 unchanged sentence
Cybersecurity.
−Removed: Sponsor, its parent Valkyrie Investments Inc., and their respective affiliates (collectively, “Valkyrie”) have adopted an
−Removed: organizational wide cybersecurity program.
−Removed: The program is administered by the Chief Compliance Officer (“CCO”) of Valkyrie
−Removed: Funds, LLC, an affiliate of the Sponsor and wholly-owned subsidiary of Valkyrie Investments Inc.
−Removed: Valkyrie’s objective, in the development
−Removed: and implementation of this comprehensive cybersecurity program, is to create effective administrative, technical, and physical safeguards
−Removed: for the protection of personal information of the organization and its clients.
−Removed: has designated the CCO to implement and maintain the cybersecurity program.
−Removed: The CCO may delegate any of the CCO’s responsibilities
−Removed: to appropriate designees as long as the CCO remains primarily responsible for compliance oversight and administration.
−Removed: The CCO will is
−Removed: responsible for:
+Added: Cybersecurity
+Added: Sponsor has adopted an organizational wide cybersecurity program.
+Added: The program is administered by the Head of IT of the Sponsor
+Added: (the “Head of IT”).
+Added: The Sponsor’s objective, in the development and implementation of this comprehensive cybersecurity
+Added: program, is to create effective administrative, technical, and physical safeguards for the protection of personal information
+Added: of the organization and its clients.
+Added: Sponsor has designated the Head of IT to implement and maintain the cybersecurity program.
+Added: The Head of IT may delegate any of
+Added: the Head of IT’s responsibilities to appropriate designees as long as the Head of IT remains primarily responsible for compliance
+Added: oversight and administration.
+Added: The Head of IT will is responsible for:
implementation of the cybersecurity program;
2 unchanged sentences
the ability of each of our third party service providers to implement and maintain appropriate
−Removed: security measures for the personal information to which we have permitted them access, and
−Removed: requiring such third party service providers by contract to implement and maintain appropriate
−Removed: security measures.
−Removed: the scope of the security measures in the cybersecurity program at least annually, or whenever
−Removed: there is a material change in our business practices that may implicate the security or integrity
−Removed: of records containing personal information.
+Added: security measures for the personal information to which we have permitted them access,
+Added: and requiring such third party service providers by contract to implement and maintain
+Added: appropriate security measures.
+Added: the scope of the security measures in the cybersecurity program at least annually, or
+Added: whenever there is a material change in our business practices that may implicate the
+Added: security or integrity of records containing personal information.
Identification
of Risks and Cybersecurity Governance
−Removed: combat internal risks to the security, confidentiality, and/or integrity of any electronic records containing personal information, and
−Removed: evaluating and improving, where necessary, the effectiveness of the current safeguards for limiting such risks, Valkyrie has identified
−Removed: the following risks that are present to its business as well as procedures to help mitigate those risks:
+Added: combat internal risks to the security, confidentiality, and/or integrity of any electronic records containing personal information,
+Added: and evaluating and improving, where necessary, the effectiveness of the current safeguards for limiting such risks, the Sponsor
+Added: has identified the following risks that are present to its business as well as procedures to help mitigate those risks:
must be communication to employees on the detailed provisions of the cybersecurity program
2 unchanged sentences
who are reasonably required to know such information.
−Removed: security measures shall be reviewed at least annually, or whenever there is a material change
−Removed: in our business practices that may reasonably implicate the security or integrity of records
−Removed: containing personal information.
−Removed: employees must return all records containing personal information, in any form, that may
−Removed: at the time of such termination be in the former employee’s possession.
−Removed: terminated employee’s physical and electronic access to personal information must be
−Removed: immediately blocked.
−Removed: Such terminated employee shall be required to surrender all keys, IDs
−Removed: or access codes or badges, business cards, and the like, that permit access to the firm’s
−Removed: premises or information.
−Removed: Moreover, such terminated employee’s remote electronic access
−Removed: to personal information must be disabled;
−Removed: his/her voicemail access, e-mail access, internet
−Removed: access, and passwords must be invalidated.
−Removed: employees’ user ID’s and passwords must be managed in accordance to Valkyrie’s
+Added: security measures shall be reviewed at least annually, or whenever there is a material
+Added: change in our business practices that may reasonably implicate the security or integrity
+Added: of records containing personal information.
+Added: employees must return all records containing personal information, in any form, that
+Added: may at the time of such termination be in the former employee’s possession.
+Added: terminated employee’s physical and electronic access to personal information must
+Added: be immediately blocked.
+Added: Such terminated employee shall be required to surrender all keys,
+Added: IDs or access codes or badges, business cards, and the like, that permit access to the
+Added: firm’s premises or information.
+Added: Moreover, such terminated employee’s remote
+Added: electronic access to personal information must be disabled;
+Added: his/her voicemail access,
+Added: e-mail access, internet access, and passwords must be invalidated.
+Added: employees’ user ID’s and passwords must be managed in accordance to the Sponsor’s
password policy.
2 unchanged sentences
screen when they are not at their desks.
−Removed: Employees are responsible for locking computer screen
−Removed: when away from workspace.
+Added: Employees are responsible for locking computer
+Added: screen when away from workspace.
must not share login information with co-workers.
−Removed: will maintain reasonably up-to-date firewall protection (if applicable) and operating system
−Removed: security patches, reasonably designed to maintain the integrity of the personal information,
+Added: Sponsor will maintain reasonably up-to-date firewall protection (if applicable) and operating
+Added: system security patches, reasonably designed to maintain the integrity of the personal
+Added: information, installed on systems processing personal information.
+Added: Sponsor will maintain reasonably up-to-date versions of system security agent software
+Added: which must include malware protection and reasonably up-to-date patches and virus definitions,
installed on systems processing personal information.
−Removed: will maintain reasonably up-to-date versions of system security agent software which must
−Removed: include malware protection and reasonably up-to-date patches and virus definitions, installed
−Removed: on systems processing personal information.
−Removed: the extent technically feasible, personal information stored on portable devices, such as
−Removed: laptops or tablets, must be password protected, as must all records and files transmitted
+Added: the extent technically feasible, personal information stored on portable devices, such
+Added: as laptops or tablets, must be password protected, as must all records and files transmitted
across public networks or wirelessly, to the extent technically feasible.
1 unchanged sentence
Associated with Remote Client Access and Funds Transfer Requests
−Removed: Valkyrie does not provide its clients with online account access nor does process funds transfer requests.
−Removed: If the firm’s business
−Removed: changes to allow for remote client access and funds transfer requests, Valkyrie will update the cybersecurity program accordingly by
−Removed: identifying the potential risks involved and implementing the appropriate safeguards to protect the client’s personal information.
+Added: the Sponsor does not provide its clients with online account access nor does process funds transfer requests.
+Added: If the firm’s
+Added: business changes to allow for remote client access and funds transfer requests, the Sponsor will update the cybersecurity program
+Added: accordingly by identifying the potential risks involved and implementing the appropriate safeguards to protect the client’s
+Added: personal information.
Associated with Vendors and Other Third Parties
−Removed: periodically conducts risk assessments with vendors and other third parties that have access to the Firm’s networks, customer data,
−Removed: and other sensitive information.
+Added: Sponsor periodically conducts risk assessments with vendors and other third parties that have access to the Firm’s networks,
+Added: customer data, and other sensitive information.
of Unauthorized Activity
−Removed: who believe their terminal or computer systems have been subjected to unauthorized activity, or has otherwise been improperly accessed
−Removed: or used, are required to report the situation to the CCO immediately to determine the course of action.
−Removed: takes the issue of security seriously.
−Removed: Firm employees who use the technology and information resources of the firm must be aware that
−Removed: they can be disciplined if they violate this policy.
−Removed: Upon violation of this policy, an employee may be subject to discipline up to and
−Removed: including discharge.
−Removed: The specific discipline imposed will be determined by a case-by-case basis, taking into consideration the nature
−Removed: and severity of the violation of the cybersecurity program, prior violations of the policy committed by the individual, state and federal
−Removed: laws and all other relevant information.
−Removed: a case where the accused person is not a firm employee, the matter shall be submitted to the CCO.
−Removed: The CCO may refer the information to
−Removed: law enforcement agencies and/or prosecutors for consideration as to whether criminal charges should be filed against the alleged violator(s).
+Added: who believe their terminal or computer systems have been subjected to unauthorized activity, or has otherwise been improperly
+Added: accessed or used, are required to report the situation to the Head of IT immediately to determine the course of action.
+Added: Sponsor takes the issue of security seriously.
+Added: Firm employees who use the technology and information resources of the firm must
+Added: be aware that they can be disciplined if they violate this policy.
+Added: Upon violation of this policy, an employee may be subject to
+Added: discipline up to and including discharge.
+Added: The specific discipline imposed will be determined by a case-by-case basis, taking into
+Added: consideration the nature and severity of the violation of the cybersecurity program, prior violations of the policy committed
+Added: by the individual, state and federal laws and all other relevant information.
+Added: a case where the accused person is not a firm employee, the matter shall be submitted to the Head of IT.
+Added: The Head of IT may refer
+Added: the information to law enforcement agencies and/or prosecutors for consideration as to whether criminal charges should be filed
+Added: against the alleged violator(s).
to the Cybersecurity Program
−Removed: CCO reviews the cybersecurity program on a periodic basis and updates the program based on changes in the firm’s business, effectiveness
−Removed: of the safeguards, and any additional risk factors that become present.
−Removed: The CCO will inform management of the results of the reviews
−Removed: and any recommendations for improved security arising out of the reviews.
−Removed: if an incident occurs that is determined to be in violation of the cybersecurity program, there shall be an immediate mandatory post-incident
−Removed: review of events and actions taken, if any, with a view to determining whether any changes in our security practices are required to
−Removed: improve the security of personal information for which the Firm is responsible.
+Added: Head of IT reviews the cybersecurity program on a periodic basis and updates the program based on changes in the firm’s
+Added: business, effectiveness of the safeguards, and any additional risk factors that become present.
+Added: The Head of IT will inform management
+Added: of the results of the reviews and any recommendations for improved security arising out of the reviews.
+Added: if an incident occurs that is determined to be in violation of the cybersecurity program, there shall be an immediate mandatory
+Added: post-incident review of events and actions taken, if any, with a view to determining whether any changes in our security practices
+Added: are required to improve the security of personal information for which the Firm is responsible.
Legal Proceedings.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.